QuimaRAT: A New Rent-a-Malware Kit That Hits Windows, Mac and Linux

Researchers at LevelBlue say the Java-based remote access tool is being sold as a subscription, starting at $150 a month, and works across all three major desktop systems.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 3 min read
Illustration: three different laptops arranged side by side on a dark desk, one Windows machine
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • Security firm LevelBlue has identified a new piece of malware called QuimaRAT that runs on Windows, macOS and Linux computers.
  • QuimaRAT is a remote access trojan, meaning software that lets a criminal secretly control someone else's computer over the internet.
  • The tool is rented out to criminals for between $150 for one month and $1,200 for lifetime access.
  • It is written in Java, a programming language that runs almost anywhere, which is why one build can attack three different operating systems.

A new piece of criminal software is doing the rounds, and it doesn't care what kind of computer you use.

Researchers at cybersecurity firm LevelBlue have named it QuimaRAT. It's a remote access trojan, a hidden program that gives a criminal a live connection into your machine, as if they were sitting at your keyboard.

The unusual part is the reach. Most desktop malware is built for Windows. QuimaRAT runs on Windows, macOS and Linux from the same codebase, which we haven't seen priced this low since OnyxC2 landed at $250 a month in June.

Why does this one work on Macs and Linux too?

Because it's written in Java, a decades-old programming language designed to run the same code on almost any device. That design choice means the criminals only have to build the tool once. Whatever operating system the victim is running, the malware does its job.

This lowers the bar considerably. A buyer doesn't need separate tools for separate targets. One subscription covers the lot.

How is it being sold?

As a service, like a streaming subscription, but for crime. This model is known as malware-as-a-service, or MaaS. Instead of writing their own hacking tools, aspiring criminals rent finished kits and point them at victims.

According to LevelBlue, first flagged by The Hacker News, QuimaRAT's pricing runs from $150 for a single month up to $1,200 for lifetime access, with a middle tier at $300. That's cheap. A serious enterprise security product costs many times more per seat.

The failure mode here is predictable. Low price plus cross-platform reach plus a ready-made control panel equals a lot of amateurs suddenly holding a working remote access tool.

What can QuimaRAT actually do?

Once it's on a machine, a remote access trojan of this class typically lets the operator watch what the user is doing, copy files, capture passwords as they're typed, activate the webcam or microphone, and drop further malicious software. LevelBlue's analysis places QuimaRAT in that bracket.

Full remote control of your device, without your knowledge.

How does it get onto a computer in the first place?

The usual way. Malicious email attachments, fake installers, and cracked software are the standard delivery routes. Nothing exotic is required. The victim clicks something they shouldn't have, and the Java payload runs.

The postmortem will say, again, that Java was already installed and nobody was watching what it did.

Should you worry if you use a Mac or Linux machine?

Yes, actually. If you've assumed malware is a Windows problem, QuimaRAT is a reason to stop. Don't run Java-based files from email. Avoid cracked apps. Keep your operating system and browser updated.

For IT teams, the operational point is blunt: your endpoint detection needs to cover the Macs and the Linux boxes, not just the Windows fleet. Most shops still haven't fixed that gap, and MaaS operators know it.

© 2026 Threat Vectr